A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when:
- `nxdomain-redirect <domain>;` is configured, and
- the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response.
This issue affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
References
Link | Resource |
---|---|
http://www.openwall.com/lists/oss-security/2024/02/13/1 | Mailing List Third Party Advisory |
https://kb.isc.org/docs/cve-2023-5517 | Vendor Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/ | Mailing List Third Party Advisory |
https://security.netapp.com/advisory/ntap-20240503-0006/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
22 Oct 2024, 14:09
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.openwall.com/lists/oss-security/2024/02/13/1 - Mailing List, Third Party Advisory | |
References | () https://kb.isc.org/docs/cve-2023-5517 - Vendor Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/ - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/ - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/ - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/ - Mailing List, Third Party Advisory | |
References | () https://security.netapp.com/advisory/ntap-20240503-0006/ - Third Party Advisory | |
CPE | cpe:2.3:a:isc:bind:9.16.32:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* cpe:2.3:a:isc:bind:9.18.18:s1:*:*:supported_preview:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:a:isc:bind:9.16.43:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:9.16.11:s1:*:*:supported_preview:*:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:isc:bind:9.16.36:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:9.16.13:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:9.18.11:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:9.16.14:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:9.16.45:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:9.16.12:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:9.18.21:s1:*:*:supported_preview:*:*:* cpe:2.3:a:isc:bind:9.16.21:s1:*:*:supported_preview:*:*:* |
|
First Time |
Fedoraproject
Fedoraproject fedora Isc bind Netapp Netapp active Iq Unified Manager Isc |
22 Aug 2024, 14:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-617 |
03 May 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Mar 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 Feb 2024, 16:27
Type | Values Removed | Values Added |
---|---|---|
References |
|
19 Feb 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary |
|
13 Feb 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
13 Feb 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-13 14:15
Updated : 2024-10-22 14:09
NVD link : CVE-2023-5517
Mitre link : CVE-2023-5517
CVE.ORG link : CVE-2023-5517
JSON object : View
Products Affected
isc
- bind
fedoraproject
- fedora
netapp
- active_iq_unified_manager
CWE
CWE-617
Reachable Assertion